Django Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2021-3281 - Vulnerability Database

Django Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2021-3281

Medium
Reference: CVE-2021-3281
Title: Django Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Overview:

In Django 2.2 before 2.2.18 3.0 before 3.0.12 and 3.1 before 3.1.6 the django.utils.archive.extract method (used by startapp --template and startproject --template) allows directory traversal via an archive with absolute paths or relative paths with dot segments.